5 ms·
What's the protocol to secure all devices/network after incident like this week? Should all hardware left behind considered possibly compromised?
by DevX101 6y ago
What's the protocol to secure all devices/network after incident like this week? Should all hardware left behind considered possibly compromised?
- TheCapn 6y agoI was thinking even just merely about physical security while this was going on. One bad actor going from room to room planting listening devices would take a short bit to weed out no?
- amenghra 6y agohttps://twitter.com/doctorow/status/1347244300527013889 https://twitter.com/doctorow/status/1347244300527013889: "Resecuring the Capitol's IT infrastructure should probably involve shredding every device, cable and thumb-drive, tearing open every light-socket and power-outlet, and even then, it will be hard to fully trust the building and its systems."
- tyre 6y agoIf this is done, does everyone lose all of their unbacked up work or is there some way to recover it safely? There are for sure internal notes, draft bills and changes, etc. on these computers that is not backed up.
- saul_goodman 6y agoHeh, congress doesn't write any legislation any more, that all happens on K-street now by lobbyists.
- blisterpeanuts 6y agoThat actually sounds like a good idea anyway. There should be a full cleaning, de-bugging, and wipe every device on a regular basis.
- dhagz 6y agoEvery administration change, at a minimum.
- amenghra 6y agohttps://twitter.com/ericgeller/status/1347226499930230785 https://twitter.com/ericgeller/status/1347226499930230785 is a good thread. Starts with: "So far, hearing that cyber risks of the Capitol attack were low. * Congress isn't one big network * Vulnerable machines held unclassified files * Hill leaks so much already that truly sensitive stuff is walled off * Rioters weren't there long enough for thorough, careful access" [...] For those wondering about the SCIFs, used for classified files and conversations, their doors were built to withstand embassy sieges, and they’re swept for bugs before every use. We haven’t seen any indication that they were even targeted, much less seriously attacked. Could one of the terrorists have seen a sensitive but unclassified email somewhere? Yes. Could there have been Russian spies in the terrorist mob? Yes."
- yabones 6y agoOnce untrusted, never trusted. Everthing in that building that plugs into the wall should be discarded and with a known good device. That includes network infrastructure and even cabling. Between this and the recent SUNBURST fiasco, there are going to be some long discussions about security policy.
- CivBase 6y agoI think that would be a good start. Then again, I also don't think it should have been so trivial for infiltrators to access content on congressional computing devices in the first place, even with physical access. I'm not sure about other devices in the building, but there's plenty of stuff going around about Pelosi's laptop in her office. Was it just left unlocked and unattended? Did it even have an OS password? If it did, was that password written down somewhere such that infiltrators could easily access it? Replacing all of the compromised tech is a good start, but clearly we need to hold our politicians to a higher standard when it comes to securing their devices.